The package is well documented, licensed, and recently released, with no install-time scripts. Its small dependency base and clean repository history help, but ongoing review capacity remains limited.
68%
Total Score
50
100
88
75
All three recent commits came from one contributor, leaving no demonstrated second maintainer to provide continuity or review.
Three commits in the last three months show recent maintenance, though the volume is light for a security-sensitive API client.
The repository name does not match the package name and its README does not mention the package, creating uncertainty about the registry-to-source relationship despite the repository being linked.
Composer is used for builds, but no security-scanning tool was detected. That leaves dependency and code scanning coverage unclear for a client handling banking data.
The repository has no security policy, which weakens the documented process for reporting and handling vulnerabilities in a security-sensitive package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^3.0 | — | — |
guzzlehttp/guzzle Version ^6.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.